One subscription, two mandates
A subscription is the supply of goods or services in exchange for repeated payments at an agreed interval. It rests on two separate contracts, and nothing requires them to line up. The first binds the customer to the merchant and sets the term, price, notice period, and cancellation terms. The second authorizes the repeated movement of money, and is called a mandate. The mandate lives outside the terms and conditions, follows different rules, and often lapses without the commercial contract being canceled. The gap between the two explains most of the problems in recurring billing, whether debits continue after a cancellation or payments stop when the customer wanted to stay.
Two families of mandates divide the world. The card mandate comes from private rules, those of the schemes, attached to a credential stored by the merchant or its provider, and no national law defines it. The bank mandate is written into an enforceable rulebook, often backed by national law. The difference shows in the proof each one requires. The first is proved by a technical flag carried in each authorization, while the second is proved by a document the creditor must be able to produce.
| Card, recurring MIT | SEPA Direct Debit Core | Direct Debit (Bacs) | Pix Automático | |
|---|---|---|---|---|
| Who writes the rules | The schemes: Visa, Mastercard, domestic networks | European Payments Council | Pay.UK | Banco Central do Brasil |
| Where consent lives | In a stored credential, plus a flag carried in each authorization | In a mandate held by the creditor, who must be able to produce it | In an instruction held by the creditor, under a Service User Number | In the payer's banking app |
| Can the customer stop it on their own? | No. They go through the merchant, or block their card | Yes, by having their bank block the mandate | Yes, by canceling with their bank; the creditor finds out through ADDACS | Yes, self-service, with immediate effect |
| Returns and disputes | Chargeback under scheme rules | No-questions-asked refund within 8 weeks; 13 months if the mandate is disputed | Direct Debit Guarantee: refund with no cap and no time limit | None. A settled payment doesn't come back |
| What breaks in practice | The credential expires before the customer leaves | Insufficient funds on the collection date | Advance notice wasn't sent, and the indemnity claim is lost automatically | The authorization is revoked and no one tells the creditor |
This distinction drives reserves. A card program reserves for chargebacks and for attrition in its stored credentials, a SEPA program reserves for eight weeks of no-questions-asked refunds, and a UK program reserves with no end date. A Brazilian program on Pix Automático reserves for no returns at all, but must absorb instant revocation. Each instrument calls for a different kind of reserve, and applying one instrument's model to another overstates the risk in one case and understates it in the other.
Credentials on file and the chaining the schemes require
Credential-on-file means storing a payment method for future charges. Visa's Stored Credential Framework, in effect since 2017 and adopted by Mastercard, turned this commercial practice into something the scheme regulates. It defines two flags. A CIT (Customer-Initiated Transaction) assumes the cardholder is present and taking action, while an MIT (Merchant-Initiated Transaction) is triggered by the merchant alone, under a mandate obtained during an earlier CIT.
The link between the initial CIT and the MITs that follow takes the form of a technical reference, sent in every authorization message. The enrollment CIT returns a transaction identifier, called the Transaction ID at Visa and the Trace ID at Mastercard, which the merchant must store. Each subsequent payment references it, along with the MIT type and an entry mode indicating a stored credential. This reference is the only proof of the mandate the issuer receives. Without it, the issuer treats the message as an unauthenticated card-not-present sale.
Initial CIT - subscriber enrollment
entry mode : e-commerce, with the "first use of a
stored credential" indicator
authentication : 3-D Secure successful (the mandate is born here)
amount : 0.00 for account verification, or the first payment
response : approved
KEEP : Transaction ID (Visa) / Trace ID (Mastercard)
this is the evidence of the card mandate
Recurring MIT - each subsequent payment
entry mode : 10 = credential on file
MIT indicator : recurring (fixed amount and frequency)
chained reference : identifier returned by the initial CIT
CVV2 cryptogram : absent - storing it is prohibited, so absence is normal
3-D Secure : absent - no one is in session
If the chained reference is missing:
the European issuer sees an unauthenticated card-not-present sale
-> decline 1A (Visa, CB) or 65 (Mastercard), meaning "authenticate"
-> no way out: no cardholder is there to authenticate
-> the payment fails, the retry fails too, and the customer leaves- The amount changes: a subscription whose price changes leaves the fixed-amount recurring category. The flag must follow, or the payment will be declined.
- The frequency changes: switching from monthly to annual starts a new series, not a variant of the old one.
- Usage becomes variable: an automatic top-up triggered by a threshold falls under unscheduled credential on file, never recurring.
- A retry after a decline is a separate MIT type, the resubmission, which must carry the amount of the original payment.
- The network token changes form without changing holder: this is what makes automatic credential updates possible without the customer having to act again.
Credential maintenance is a service you sign up for, separate from simply storing the payment method. The schemes run updater services, chiefly Visa Account Updater and its real-time version, and Mastercard's Automatic Billing Updater. Network tokens issued under the EMVCo specification survive card reissuance, because the token stays stable and only its internal mapping changes. A subscription program that stores card numbers in the clear, without using one of these services, loses a share of its base every year as cards expire or are reissued.
What the schemes require of a subscription merchant
The MCC, or merchant category code, is a 4-digit code that classifies a merchant by business type. MCC 5968, Direct Marketing — Continuity/Subscription Merchants, covers merchants that bill on a continuing basis. The code has three distinct effects. It feeds issuer scoring, determines interchange rates, and triggers closer monitoring of dispute rates. A subscription merchant classified under another MCC gets better approval rates in the short term, but loses the category's protection at the first dispute.
Network rules have tightened around one specific case: the free trial that converts to a paid subscription. Visa and Mastercard impose a chain of requirements on this flow. Consent must be collected separately from the purchase, and a reminder must precede the conversion. A receipt must follow each charge. The statement descriptor must identify the merchant clearly enough for the cardholder to recognize it without effort, and cancellation must remain available online, as easily as sign-up.
| Timing | What's required | What to monitor in production |
|---|---|---|
| Enrollment | Explicit consent to storing the credential, separate from accepting the terms and conditions; authentication of the initial transaction | Consent timestamp, record of the flow, presence of the chaining identifier returned by the network |
| End of trial | Reminder sent to the customer before the first paid charge, stating the amount and date | Dispute rate within 30 days of conversion, the metric that exposes a missing or unclear reminder |
| Every payment | Receipt to the customer, recognizable statement descriptor, correct MIT flag | Share of authorizations carrying the chained reference; approval rate gap between flagged and unflagged MITs |
| Cancellation | Online cancellation path, debits actually stopped, confirmation to the customer | Time between the cancellation request and the actual end of the series; disputes arise in that window |
Subscription disputes have their own reason codes. At Visa, condition 13.2 covers a canceled recurring transaction, while Mastercard uses reason code 4841, Cancelled Recurring or Digital Goods Transactions. The merchant's defense rests on three pieces of evidence: proof of the initial consent, proof of the information provided before the charge, and proof that no cancellation had occurred by the billing date. The case is decided on those three items, and no commercial argument makes up for a missing one.
Bank mandates: what they cost, what they deliver
A direct debit is a debit from an account initiated by the creditor, under a mandate the account holder gave in advance. In most mature markets, recurring bills go through this channel rather than cards. Direct debit costs a fraction of a card authorization, is unaffected by credential expiry, and its success rate depends on a single variable: available funds on the collection date. In exchange, it exposes the creditor to a revocability cards don't have, and it requires bank sponsorship that not every creditor can get.
| Market | Instrument | Operator | Advance notice to payer | What sets it apart |
|---|---|---|---|---|
| SEPA area | SEPA Direct Debit Core and B2B | European Payments Council (scheme), since 2009 | 14 calendar days by default, can be shortened by agreement | Two rulebooks with opposite rights: no-questions-asked refund within 8 weeks under Core, none under B2B |
| United Kingdom | Direct Debit via Bacs | Pay.UK, operated by Vocalink (Mastercard), since 1968 | 10 business days by default, set in the sponsorship agreement | Direct Debit Guarantee with no cap and no time limit; access requires a Service User Number obtained from your bank |
| United States | ACH debit, SEC codes PPD and WEB | Nacha (rules), FedACH and EPN (clearing), since 1972 | 10 calendar days before any debit in a different amount from the previous one | Unauthorized-debit returns open for 60 calendar days; account validation required on the first WEB debit |
| Sweden | Autogiro | Bankgirot, since 1969 | Per the service agreement | Never migrated to SEPA: Swedish recurring payments run in kronor on a domestic rail |
| Denmark | Betalingsservice | Mastercard Payment Services, since 1974 | Built into the system cycle | Centrally managed mandates and a fixed monthly cycle: the billing calendar is imposed, not chosen |
| Norway | AvtaleGiro | Finance Norway / Mastercard Payment Services | Notification by the payer's bank | The payer sees and approves upcoming payments in online banking before they go out |
| Netherlands | Incassomachtigen | Currence, since 2016 | SEPA Direct Debit rules | SEPA mandates are signed with bank authentication, the only such system rolled out at national scale |
| Switzerland | LSV+ and Debit Direct | SIX (LSV+) / PostFinance (Debit Direct) | Depends on the procedure used | Non-SEPA procedures: a creditor collecting in Swiss francs integrates them separately from its euro flows |
| Singapore | GIRO | Banking Computer Services for the Association of Banks in Singapore, since 1984 | Set by the biller | Dominant for recurring bills and taxes, despite a mature local instant payment system |
| United Arab Emirates | UAEDDS | Central Bank of the UAE, since 2012 | Per the registered mandate | Mandates registered with the central bank, designed to replace post-dated checks |
US ACH differs from every other rail in having no mandate in the European sense. It has no standardized creditor identifier, no reference carried in the message, and no sequence control. The authorization that takes its place varies in form depending on the channel through which it is obtained, and is declared to the network with a three-letter code. The risk sits with the bank that enters the transaction into the network, not with a scheme. A US creditor therefore negotiates its program terms with its bank, which applies its own risk appetite.
The next generation: mandates created in the payer's app
A native mandate is a direct debit authorization created and stored in the payer's banking app rather than in the creditor's records. The model emerged in Asia-Pacific, then in Latin America. The mandate becomes visible to the payer, listed among their active authorizations, and can be suspended or revoked in three taps without going through the creditor. The underlying rail is instant, so collection is too, and the creditor gains a higher success rate and immediate settlement. What it loses is control over when the series stops, since that decision is made in an app it can't see.
| System | Operator | Since | What it means for the creditor |
|---|---|---|---|
| PayTo | NPP Australia (Australian Payments Plus) | 2022 | Mandate created, capped, and revoked in the banking app; instant settlement, with no refund guarantee comparable to direct debit |
| Pix Automático | Banco Central do Brasil | 2025 | Payees must be legal entities, payer fees prohibited, frequency set at authorization; no dispute possible after settlement |
| UPI AutoPay | National Payments Corporation of India | 2020 | Enrollment in seconds in the UPI app; immediate rejection on failure, so a same-day retry is possible |
| e-NACH | National Payments Corporation of India | 2016 | Longer enrollment flow, but suited to large amounts: loan repayments, insurance premiums, systematic investment plans |
| DuitNow AutoDebit | Payments Network Malaysia, supervised by Bank Negara Malaysia | – | The direct debit component of the PayNet lineup: the piece missing from DuitNow Transfer and FPX, both payer-initiated |
| Variable Recurring Payments | Standard published by Open Banking Limited (UK) | – | Capped mandate held in the banking app, on the Faster Payments rail; sweeping is live, commercial VRP not yet at scale |
Pix Automático is the best-documented system of this generation, since Brazilian regulation sets out its collection mechanics in detail. The payment instruction is sent between two and 10 days before the scheduled settlement date. Settlement itself has two mandatory windows, midnight to 8 a.m. and 6 p.m. to 9 p.m., Brasília time. A failure triggers a new attempt the same day, preceded by a notification asking the payer to add funds to the account. Attempts can continue for up to seven days if the authorization allows it.
Authenticate once, charge a hundred times
Authentication of a recurring series follows a principle shared by every regime. The customer is strongly authenticated once, at enrollment, and subsequent payments run without any further action on their part. Regimes then differ on how far that exemption extends, what amounts it covers, and when it stops applying.
In the European Economic Area, two texts work together. Article 14 of Delegated Regulation (EU) 2018/389 exempts from strong customer authentication recurring transactions of the same amount to the same payee. Authentication applies only to the first payment. Merchant-initiated transactions follow separate reasoning: the European Banking Authority placed them out of scope in its June 2019 opinion, because the payer doesn't initiate them. In both cases the exemption depends on the flag carried in the authorization message, and a missing or wrong flag removes it.
| Region | Applicable law | At enrollment | For subsequent payments |
|---|---|---|---|
| European Economic Area | Delegated Regulation (EU) 2018/389, Art. 14; European Banking Authority opinion of June 2019 on MITs | Strong authentication required | None, if the series is flagged and chained correctly |
| India | Digital Payments – E-mandate Framework, 2026, Reserve Bank of India | Strong authentication required, no exceptions | None up to ₹15,000 per transaction; the threshold rises to ₹1 lakh (₹100,000) for insurance premiums, mutual fund subscriptions, and credit card bill payments |
| Brazil | Pix Automático, Resolução BCB nº 402 of July 22, 2024 | Authorization given in the payer's app, through one of the four prescribed flows | None; the payer can still cancel a scheduled payment |
| Australia | PayTo rules, NPP Australia | Mandate created and authenticated in the payer's banking app | None; suspension and revocation remain self-service |
| United States | Nacha rules; Regulation E (12 CFR 1005) | Authorization whose form depends on the SEC code; account validation on the first WEB debit | None; the unauthorized-debit return stays open for 60 calendar days |
The Indian framework moves the point where a series can break, by letting the payer refuse each payment after seeing it announced. Every debit must be preceded by a pre-debit notification sent at least 24 hours in advance, stating the payee's name, the amount, the date and time, the mandate reference, and the purpose. The payer can decline transaction by transaction. Revoking a mandate requires strong authentication, and charging the customer for using the e-mandate service is prohibited.
The declined payment: read, fix, retry
A failed payment falls into one of two families, depending on whether the payment instrument is still usable. In the first, the instrument no longer exists in the form the creditor has on file, because the card expired, the account was closed, or the mandate was revoked. No re-presentment will succeed. In the second, the instrument is still valid and only the funds were missing at the time of the debit, so a later attempt has a good chance of succeeding. Treating the first family like the second produces pointless retries that the network bills for and sometimes penalizes.
| Rail | Code or file | What it means | What to do |
|---|---|---|---|
| Card | 51 | Insufficient funds | Deferred retry, timed to a payday |
| Card | 54 | Expired card | The credential is dead: update it through the scheme's service, or get a new card from the customer |
| Card | 1A / 65 | Strong authentication required | Missing MIT flag: fix the integration, don't replay the payment |
| Card | 05 | Generic issuer decline | One retry, no more; beyond that, you're using up a billed retry budget |
| SEPA | AM04 | Insufficient funds | Re-presentment allowed within rulebook limits |
| SEPA | MD01 | No mandate or invalid mandate | Stop the series and get a new mandate signed; any other action makes the case worse |
| SEPA | MS03 | Reason not specified | Treat it as a payer refusal: the bank won't say more, but the customer will |
| SEPA | AC04 | Account closed | New account details required; never re-present |
| ACH | R01 | Insufficient funds | Nacha allows up to two re-presentments after an R01 |
| ACH | R10 | The account holder reports the debit as unauthorized | Sixty calendar days after settlement: the real cost of a US consumer debit |
| Bacs | ARUDD file | The cycle's unpaid items, with reason codes | It arrives on settlement day itself: treasury must plan for it, not discover it |
| Bacs | ADDACS file | The payer has canceled their instruction | The customer is gone. Cut off the service and stop the series before calling |
The networks cap retries. Visa limits new attempts on a declined transaction to 15 in 30 days, with fees beyond that, and Mastercard runs a comparable program to monitor excessive retries. Some declines are final, such as a stolen card, an invalid number, or suspected fraud, and retrying them exposes the merchant to acquirer penalties. A merchant's retry policy therefore operates within a limit set by the scheme, and going over it costs attempt fees and penalties.
Cancellation: what the law requires, market by market
Canceling a subscription is how the customer ends the contract and, in principle, the debits that come with it. Several markets now require cancellation to be as easy as sign-up, and available through the same channel. The laws agree on the principle and differ on the details, since each prescribes a different flow, with its own wording, deadlines, and evidence. Cancellation handling moves from customer service to compliance, then to online flow engineering.
| Market | Legal basis | What it requires | Impact on payments |
|---|---|---|---|
| Germany | § 312k BGB, the Kündigungsbutton (cancellation button) | A button labeled “Verträge hier kündigen” (cancel contracts here), clearly legible and always accessible, then a confirmation page with “jetzt kündigen” (cancel now) | Cancellation becomes a timestamped, legally binding product event, rather than an exchange of emails |
| California | Automatic Renewal Law, as amended by AB 2863 | Cancellation through the sign-up channel, a direct online link or button, an annual reminder, 7 to 30 days' notice before any price change | Applies to contracts entered into, amended, or renewed on or after July 1, 2025 |
| US (federal) | Restore Online Shoppers' Confidence Act, 15 U.S.C. § 8403 | Clear disclosure before the charge, express consent, a simple mechanism to stop recurring charges | The FTC's click-to-cancel rule was vacated by the Eighth Circuit Court of Appeals in July 2025; ROSCA remains the basis for enforcement |
| European Union | Directive 2011/83/EU on consumer rights | 14-day withdrawal period for distance contracts | The right applies to the contract, not the payment mandate: the mandate must be canceled separately |
| India | Digital Payments – E-mandate Framework, 2026 | Pre-debit notification 24 hours before each debit, the right to decline transaction by transaction, mandate revocation with strong authentication | Some churn is triggered the day before the debit, not at renewal |
| Brazil | Pix Automático, Resolução BCB nº 402 | Immediate revocation from the payer's app, which also ends the recurrence | No refund window: the mandate dies, and payments already settled stay with the creditor |
| Australia | PayTo rules, NPP Australia | Real-time mandate suspension and revocation in the banking app | The creditor finds out at the next rejection, never before |
| United Kingdom | Direct Debit Guarantee, Pay.UK | Immediate, full refund of an erroneous direct debit by the payer's bank | No cap and no time limit; the bank then recovers the amount from the creditor through an indemnity claim |
These requirements share two features. The first is their subject: recent laws regulate the cancellation flow, not the contract's content, by requiring a button, a confirmation page, and a deadline for it to take effect. The second is the gap between the legal act and its technical execution. Canceling a contract never automatically ends a payment mandate, and ending the mandate doesn't cancel the contract. A customer can have canceled properly and still be debited, just as they can have blocked their mandate without ever canceling.
Running a multi-market subscription program
An international subscription program rarely fails because of its product, and almost always because of its payment collection mechanics, market by market and at the same points. Opening a country therefore means revisiting four collection decisions that are independent of the product sold: the choice of instruments, the quality of recurring-series flagging, separate measurement of the two kinds of churn, and how to set reserves.
- Check the portability of tokens and network references in every provider contract before signing, the only time you have leverage.
- Classify your MCC honestly: a subscription merchant filed under another code loses its category's protection at the first dispute.
- Archive the enrollment flow with timestamp, IP address, and version of the accepted terms: it is the missing piece in nine out of ten dispute cases.
- Send advance notice wherever it is required, and keep a record. On Bacs, failing to send it means losing the indemnity claim without review.
- Set a retry policy by code, with an attempt cap below the scheme's, and stop immediately on final declines.
- Measure the first-attempt rate alongside the post-retry rate, by market, instrument, and provider.
- Build a single online cancellation flow, aligned with the most demanding regime, plus the mandatory local wording.
- Document how mandates end in both directions: contract cancellation that stops the series, and mandate revocation that cuts off the service.